7.5
CVE-2023-5499
- EPSS 0.26%
- Veröffentlicht 10.10.2023 14:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:54
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages, SOS device locations and device configurations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Reachfargps ≫ Reachfar Gps Firmware Version28
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.497 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| cve-coordination@incibe.es | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.